Show filters
250 Total Results
Displaying 231-240 of 250
Sort by:
Attacker Value
Unknown
CVE-2004-0199
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
0
Attacker Value
Unknown
CVE-2003-0818
Disclosure Date: March 03, 2004 (last updated February 22, 2025)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
0
Attacker Value
Unknown
CVE-2003-0825
Disclosure Date: March 03, 2004 (last updated February 22, 2025)
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1759
Disclosure Date: January 21, 2004 (last updated February 22, 2025)
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
0
Attacker Value
Unknown
CVE-2004-1760
Disclosure Date: January 21, 2004 (last updated February 22, 2025)
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
0
Attacker Value
Unknown
CVE-2003-0914
Disclosure Date: December 15, 2003 (last updated February 22, 2025)
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
0
Attacker Value
Unknown
CVE-2003-0659
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.
0
Attacker Value
Unknown
CVE-2003-0660
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.
0
Attacker Value
Unknown
CVE-2003-0717
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
0
Attacker Value
Unknown
CVE-2003-0711
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.
0